53
Websites have a new way to spy on visitors: Analyzing their SSD activity
(arstechnica.com)
A nice place to discuss rumors, happenings, innovations, and challenges in the technology sphere. We also welcome discussions on the intersections of technology and society. If it’s technological news or discussion of technology, it probably belongs here.
Remember the overriding ethos on Beehaw: Be(e) Nice. Each user you encounter here is a person, and should be treated with kindness (even if they’re wrong, or use a Linux distro you don’t like). Personal attacks will not be tolerated.
Subcommunities on Beehaw:
This community's icon was made by Aaron Schneider, under the CC-BY-NC-SA 4.0 license.
I wonder if you could setup a virtual drive that gets picked up as an SSD and then automate and randomize everything that happens within it so it’s just noise. The problem is that this hack probably gives insight into every drive on the system, so the exploit would still grab that data; it would just run alongside the bullshit stream of data.
the attack should only have insight into the abstracted storage provided by the browser, so your idea of a virtual device that spits out random timing results is probably reasonable.
the issue is that timing being random, in and of itself, is a potential fingerprint when combined with other data from your browser - unless everyone is doing it as well.
all I can say is I give thanks for noscript every single day.